Debian Bug report logs -
#313615
License conflict makes binary undistributable
Reported by: "Grzegorz B. Prokopski" <gadek@sablevm.org>
Date: Tue, 14 Jun 2005 16:33:02 UTC
Severity: grave
Found in version 1.8.7-1
Done: Martin Michlmayr <tbm@cyrius.com>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded to debian-bugs-dist@lists.debian.org, Alberto Gonzalez Iniesta <agi@inittab.org>:
Bug#313615; Package libapache-mod-security.
(full text, mbox, link).
Acknowledgement sent to "Grzegorz B. Prokopski" <gadek@sablevm.org>:
New Bug report received and forwarded. Copy sent to Alberto Gonzalez Iniesta <agi@inittab.org>.
(full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
Package: libapache-mod-security
Severity: grave
Justification: GPL conflicts with APL and makes binary undistributable
Version: 1.8.7-1
According to http://packages.debian.org/stable/web/libapache2-mod-security
the copyright file contains BSD style license. However the LICENSE file
clearly contains the GNU GPL license. This is not only an issue of
consistency. GNU GPL is known to be incompatible with previous and current
versions of Apache license.
Therefore if this module is a derived work of Apache-licensed code, then the
license conflict prevents it from being distributed (as a binary, at least).
I am afriad that it IS a derived work, given, for example, that its source
files include numerous APL-licensed headers.
Cheers,
Grzegorz B. Prokopski
--
Grzegorz B. Prokopski <gadek@debian.org>
Debian GNU/Linux http://www.debian.org
SableVM - LGPL'ed JVM http://www.sablevm.org
Why SableVM ?!? http://devel.sablevm.org/wiki/WhySableVM
Message sent on to "Grzegorz B. Prokopski" <gadek@sablevm.org>:
Bug#313615.
(full text, mbox, link).
Message #8 received at 313615-submitter@bugs.debian.org (full text, mbox, reply):
This bug report raised the issue :
http://bugs.debian.org/313615
of an apache module (libapache-mod-security) being gpl while
using apache licenced headers .
I have checked the module source and it does not ship with its
own version of the apache headers.
It seems to me this is not an issue as modules resolves their
symbols at runtime so the "library" can be bsd or apache licenced
and the module gpl .
Though this bug report also describe such modules as being
derived works which makes some sense ...
Thank you for any clue on this issue.
Regards
Alban
Information forwarded to debian-bugs-dist@lists.debian.org, Alberto Gonzalez Iniesta <agi@inittab.org>:
Bug#313615; Package libapache-mod-security.
(full text, mbox, link).
Acknowledgement sent to MJ Ray <mjr@phonecoop.coop>:
Extra info received and forwarded to list. Copy sent to Alberto Gonzalez Iniesta <agi@inittab.org>.
(full text, mbox, link).
Message #13 received at 313615@bugs.debian.org (full text, mbox, reply):
I think the section in the GPL FAQ at
http://www.gnu.org/licenses/gpl-faq.html#GPLPluginsInNF
applies, even though Apache is not non-free.
libapache-mod-chroot, libapache-mod-witch, libapache2-mod-fcgid,
libapache2-mod-ldap-userdir, libapache2-mod-xslt are also GPL.
If this is a bug, it looks like those may have similar bugs.
A common solution seems to be to get permission to link to
an APL'd work as an exception. Upstream looks alive. If
they're willing, it may be the simplest fix.
libapache2-mod-ldap-userdir has an exception for OpenSSL already.
Good luck!
--
MJ Ray (slef), K. Lynn, England, email see http://mjr.towers.org.uk/
Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#313615; Package libapache-mod-security.
(full text, mbox, link).
Acknowledgement sent to Alberto Gonzalez Iniesta <agi@inittab.org>:
Extra info received and forwarded to list.
(full text, mbox, link).
Message #18 received at 313615@bugs.debian.org (full text, mbox, reply):
On Wed, Jun 15, 2005 at 10:46:06AM +0100, MJ Ray wrote:
> I think the section in the GPL FAQ at
> http://www.gnu.org/licenses/gpl-faq.html#GPLPluginsInNF
> applies, even though Apache is not non-free.
>
> libapache-mod-chroot, libapache-mod-witch, libapache2-mod-fcgid,
> libapache2-mod-ldap-userdir, libapache2-mod-xslt are also GPL.
> If this is a bug, it looks like those may have similar bugs.
>
> A common solution seems to be to get permission to link to
> an APL'd work as an exception. Upstream looks alive. If
> they're willing, it may be the simplest fix.
>
> libapache2-mod-ldap-userdir has an exception for OpenSSL already.
>
Thanks a lot for the tip! I'll talk with upstream about this. I'm sure
he'll add the permission to the license.
Regards,
Alberto
--
Alberto Gonzalez Iniesta | Formación, consultoría y soporte técnico
agi@(inittab.org|debian.org)| en GNU/Linux y software libre
Encrypted mail preferred | http://inittab.com
Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3
Information forwarded to debian-bugs-dist@lists.debian.org, Alberto Gonzalez Iniesta <agi@inittab.org>:
Bug#313615; Package libapache-mod-security.
(full text, mbox, link).
Acknowledgement sent to Adam Conrad <adconrad@0c3.net>:
Extra info received and forwarded to list. Copy sent to Alberto Gonzalez Iniesta <agi@inittab.org>.
(full text, mbox, link).
Message #23 received at 313615@bugs.debian.org (full text, mbox, reply):
Hi, just a reminder on this bug. Did you ever get around to talking to
upstream about this license conflict? Note that, because apache almost
always links to libssl, they'll need a license exception for both Apache
and OpenSSL, as most people read things. (I don't necessarily read it
that way, but better safe than sorry, I guess).
... Adam
Reply sent to Martin Michlmayr <tbm@cyrius.com>:
You have taken responsibility.
(full text, mbox, link).
Notification sent to "Grzegorz B. Prokopski" <gadek@sablevm.org>:
Bug acknowledged by developer.
(full text, mbox, link).
Message #28 received at 313615-done@bugs.debian.org (full text, mbox, reply):
libapache-mod-security has been removed from Debian because it is
undistributable for legal reasons. See #313615
--
Martin Michlmayr
http://www.cyrius.com/
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Sun, 17 Jun 2007 15:35:30 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Thu Jan 11 03:26:59 2018;
Machine Name:
beach
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.